PT-2024-24281 · Ibm · Ibm Mq

Published

2024-06-28

·

Updated

2024-08-01

·

CVE-2024-31919

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions IBM MQ versions 9.0 LTS through 9.3 CD
Description The issue is caused by an error processing messages when an API Exit using MQBUFMH is used, leading to a denial of service attack in certain configurations.
Recommendations For IBM MQ versions 9.0 LTS through 9.3 CD, consider disabling the API Exit using MQBUFMH as a temporary workaround to minimize the risk of exploitation. Restrict access to the affected configurations to prevent denial of service attacks until a patch is available.

Fix

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2024-31919

Affected Products

Ibm Mq